MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eb2c51d9b2d9e27bcf29aaa784a4738befab6134d18bfea0fa574bba52646b3f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RevengeRAT


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: eb2c51d9b2d9e27bcf29aaa784a4738befab6134d18bfea0fa574bba52646b3f
SHA3-384 hash: 1a58a02a676f00e901595eb6dccbc89900fd3c9c92bd3a32eeecf09792ede1254fd17aac80ec74ad84d5f9530da20583
SHA1 hash: d8364e8bb56d53746123bf3fb4e059bbfac83b5b
MD5 hash: eb257e3c0ec17d0d5ce7534003bb385e
humanhash: rugby-diet-beryllium-emma
File name:NMPyKHCz.exe
Download: download sample
Signature RevengeRAT
File size:14'848 bytes
First seen:2020-10-27 22:02:20 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'748 x AgentTesla, 19'652 x Formbook, 12'246 x SnakeKeylogger)
ssdeep 192:z+8C+EKS0O9ejYTDG8bcp4LlSAenieXubWyD9JEBkGxVXUZqoNfRJ0:zNVjYTDG8gpSdeXTyD3EnxtoN8
Threatray 32 similar samples on MalwareBazaar
TLSH F4623A09B7EC4739C1BD07BC0CB242256371E5A39A62C71F1CD890FE8992BD55B20BE8
Reporter pmelson
Tags:exe Revenge RevengeRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
565
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Using the Windows Management Instrumentation requests
Sending a custom TCP request
Creating a window
Result
Threat name:
RevengeRAT
Detection:
malicious
Classification:
troj.evad
Score:
72 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Potential time zone aware malware
Yara detected RevengeRAT
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Backdoor.RevengeRAT
Status:
Malicious
First seen:
2020-10-28 00:03:39 UTC
AV detection:
27 of 29 (93.10%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Checks processor information in registry
Malware Config
C2 Extraction:
52.172.142.36:333
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RevengeRAT

Executable exe eb2c51d9b2d9e27bcf29aaa784a4738befab6134d18bfea0fa574bba52646b3f

(this sample)

Comments